2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-52175MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Uno (miuno...
CVE-2023-7069MEDIUM5.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'...
CVE-2023-5390MEDIUM5.3An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion Contro...
CVE-2023-50166MEDIUM6.1Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
CVE-2023-47116MEDIUM5.3Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior t...
CVE-2023-6780MEDIUM5.3An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the sy...
CVE-2023-5992MEDIUM5.9A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant...
CVE-2023-7043MEDIUM5.5Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with t...
CVE-2023-50357MEDIUM5.4A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gai...
CVE-2023-50356MEDIUM6.5SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation...
CVE-2023-2439MEDIUM5.4The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up...
CVE-2023-46230MEDIUM4.9In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.
CVE-2023-36259MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbi...
CVE-2023-7225MEDIUM5.4The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and heig...
CVE-2023-51813MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote at...
CVE-2023-37571MEDIUM6.1Softing TH SCOPE through 3.70 allows XSS.
CVE-2023-4554MEDIUM6.5Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Serv...
CVE-2023-4553MEDIUM5.3Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder...
CVE-2023-30970MEDIUM6.5Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated use...
CVE-2023-22836MEDIUM5.4In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from t...
CVE-2023-40551MEDIUM5.1A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposu...
CVE-2023-40550MEDIUM5.5An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensi...
CVE-2023-40549MEDIUM5.5An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE bin...
CVE-2023-40546MEDIUM5.5A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new varia...
CVE-2023-7200MEDIUM6.1The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now